
CVE-2021-44228-docker-example
Docker-based demonstration of CVE-2021-44228 (Log4Shell) exploitation, featuring a vulnerable Java server, malicious LDAP server, and data…

Docker-based demonstration of CVE-2021-44228 (Log4Shell) exploitation, featuring a vulnerable Java server, malicious LDAP server, and data…

Educational CVE PoC for a TOCTOU file-permission race in Flask; uses symlink replacement during the check-open window to disclose sensitive files.

Hide files inside images: encrypted, signed, deniable, and JPEG-robust. Python CLI and library with built-in steganalysis and an in-browser demo.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Step-by-step demonstration of CVE-2021-29447, a WordPress Media Library XXE vulnerability leaking sensitive files via crafted WAVE uploads, including…

This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

CLI tool for structured Telegram OSINT data collection. Scrapes members, messages, invite links, and user metadata from public/private groups,…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

A proof of concept crypto virus to spread user awareness about attacks and implications of ransomwares. Phirautee is written purely using PowerShell…

Youtube as C2 channel - Control Windows systems uploading QR videos to Youtube

Proof-of-concept exploiting an undocumented Muse dictation endpoint setting, letting a local unprivileged process redirect dictation traffic to…

C# Tool to interact with MS Exchange based on MS docs

MAD-CAT (Meow Attack Data Corruption Automation Tool) is a comprehensive security tool designed to simulate data corruption attacks against multiple…

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

A python3 script that uses cl1p website to send and receive secret messages

Research related to the Power Tracks discovered in market microstructure.